Data Protection and Privacy 2025

MEXICO Law and Practice Contributed by: Luciano Pérez, Ana Paula Silva and Allan Pastor, Nader Hayaux & Goebel

administrative procedures handled by the INAI. For further reference to the fines imposed by the INAI as a result of these procedures, please refer to section 1.4 Data Protection Fines in Practice . 2.3 Collective Redress Mechanisms In Mexico, there are no collective redress mech - anisms specifically provided for under the Mexi - can DPRs. Collective redress mechanisms are available in Mexico for civil regulations and con - sumer protection laws. 3. Data Regulation on IoT Providers, Data Holders and Data Processing Services 3.1 Objectives and Scope of Data Regulation Mexico does not have specific regulations gov - erning IoT services as seen in other countries. Instead, the use of IoT services, as well as the rights and obligations of data subjects and data processing services, are regulated under the general framework of the Mexican DPRs. Conse - quently, IoT-related activities must adhere to the principles established in these regulations and data subjects can exercise their ARCO Rights as described in 1.3 Enforcement Proceedings and Fines . 3.2 Interaction of Data Regulation and Data Protection In Mexico, data regulation and data protection are regulated in the Mexican DPRs. The inter - play between regulation and protection is evi - dent in several key aspects. Data controllers must implement comprehensive privacy poli - cies, obtain informed consent before processing data, and ensure transparency in their practices. Specific obligations include securing personal data through physical, technical and adminis -

trative measures, and providing data subjects with mechanisms to exercise their rights ARCO Rights. 3.3 Rights and Obligations Under Applicable Data Regulation Processing of data (including IoT services) pro - cessing must comply with the following obliga - tions. • Obtain consent: collect and process personal data only after obtaining the data subject’s consent (the type of consent will depend on the type of data to be processed), except in cases where exceptions apply. • Provide a privacy notice: deliver a privacy notice that includes, among others, the pur - poses of data processing, transfers to be car - ried out, types of data collected, and rights of the data subjects. • Data quality: ensure that the personal data collected is accurate, relevant and up to date for its intended purposes. • Data security: implement appropriate techni - cal, physical and administrative measures to protect personal data from unauthorised access, loss or damage. • Guarantee ARCO Rights: allow data subjects to exercise their ARCO Rights and provide mechanisms and procedures that comply with the Mexican DPRs for their exercise. • Retention period: store personal data only for the duration necessary to fulfil the purposes stated in the privacy notice. • Internal procedures: establish internal poli - cies, procedures and training to ensure com - pliance with the Mexican DPRs, including the appointment of a Data Protection Officer. • Data breach notification: notify data subjects in compliance with the requirements set forth in the Mexican DPRs if the data controllers are subject to a data breach.

327 CHAMBERS.COM

Powered by